linzhengen/ddd-gin-admin
65.6
Weak · 21 September 2026
7.9k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a Go-based administrative platform built on a Domain-Driven Design architecture, providing a RESTful API for managing users, roles, and menus. It implements Role-Based Access Control (RBAC) using Casbin to enforce permissions and supports JWT authentication with pluggable token storage. The application offers full CRUD capabilities for administrative entities, secured by middleware that handles rate limiting, CORS, and distributed tracing.
Features
Added database initialization scripts for MySQL and PostgreSQL
New SQL scripts have been added to the project to facilitate the initial setup of the database environment. The \scripts/init\_mysql.sql\ file creates the \gin-admin\ database using the \utf8mb4\ character set, while \scripts/init\_postgres.sql\ creates the \gin-admin\ database with UTF-8 encoding and specific locale settings for PostgreSQL.
scripts · high confidence
Added database transaction management infrastructure
A new repository implementation for database transactions has been introduced in the infrastructure layer. This component provides an \Exec\ method that automatically wraps user-provided functions in a database transaction, ensuring atomicity for operations that modify data. It also includes logic to detect and respect existing transaction contexts, preventing nested transaction errors when the function is called within an already active transaction.
app/infrastructure/trans · high confidence
Added in-memory and Redis-backed CAPTCHA generation and verification
The \pkg/captcha\ package now provides a complete solution for generating and verifying image-based CAPTCHAs. It includes core logic for creating random digit sequences, rendering them as distorted PNG images with background noise, and verifying user input. The system uses a pluggable storage backend: a default in-memory store with garbage collection is provided out-of-the-box, and a Redis-backed store is also available for distributed environments, allowing CAPTCHA state to be shared across multiple application instances.
pkg/captcha · high confidence
Added menu action and menu action resource persistence layers
New infrastructure files have been added to persist menu actions and menu action resources. The \menuaction\ package introduces a \Model\ mapping to the \menu\_actions\ table and a repository supporting CRUD operations and querying by menu ID. The \menuactionresource\ package adds a \Model\ for the \menu\_action\_resources\ table and a repository that links resources to actions, including specific logic to handle SQLite compatibility by using a two-step query for deleting resources by menu ID.
app/infrastructure/menu/menuactionresource · high confidence
Added mock API handlers and regenerated Swagger documentation
This change introduces mock implementations for the API layer, adding handler stubs for HealthCheck, Login, Menu, Role, and User endpoints in the \app/interfaces/api/handler/mock\ directory. These mock handlers are wired together using Google Wire and include Swagger annotations to define API signatures. Correspondingly, the Swagger documentation files (\docs.go\, \swagger.json\, and \swagger.yaml\) have been regenerated to reflect these new API definitions, ensuring the API documentation is synchronized with the mock interface layer.
app/interfaces/api/handler/mock, app/interfaces/api/swagger · high confidence
Added role persistence layer with GORM repository
The application now includes a concrete GORM-based repository for managing user roles, located in app/infrastructure/user/role. This change introduces the database model mapping to the 'roles' table and implements the full CRUD lifecycle (Query, Get, Create, Update, Delete, UpdateStatus), enabling the system to persist and retrieve role entities from the database.
app/infrastructure/user/role · high confidence
Added role-menu mapping persistence layer
The application now includes a new repository implementation for managing the relationship between roles and menus. This change introduces the database model for the \role\_menus\ table and provides CRUD operations (create, read, update, delete) as well as specific queries for filtering by role ID, enabling the system to persist and retrieve role-based menu access configurations.
app/infrastructure/user/rolemenu · high confidence
Added structured logging package with context-aware fields
Introduced a new \pkg/logger\ module that wraps the Logrus library to provide structured logging capabilities. This package enables automatic injection of contextual metadata—including trace IDs, user IDs, tags, and stack traces—into log entries via context values, allowing for easier debugging and observability in distributed systems.
pkg/logger · high confidence
Added user-role persistence layer
The application now includes a GORM-based repository for managing user roles, introducing a new \user\_roles\ database table with \user\_id\ and \role\_id\ columns. This infrastructure component enables the system to create, read, update, delete, and query user-role associations, including filtering by specific user IDs and handling pagination.
app/infrastructure/user/userrole · high confidence
Initial API router setup with authentication, RBAC, and core resource endpoints
The API router is now initialized to handle requests under the /api/v1 prefix. It enforces user authentication via middleware (skipping public login paths) and applies Casbin-based Role-Based Access Control (RBAC) for protected routes. The router exposes endpoints for user login, logout, password updates, and token refresh, as well as full CRUD operations for managing menus, roles, and users.
app/interfaces/api/router · high confidence
Initial CLI entry point for the RBAC scaffolding application
The application now includes a main entry point (main/main.go) that initializes the CLI using urfave/cli v3. This entry point defines the application version as 0.5.0 and exposes a 'web' subcommand to start the server. The 'web' command requires configuration for the server settings (conf), Casbin model (model), and optionally allows specifying default menus (menu) and a static file directory (www). It delegates the actual server startup to the injector package, passing these configuration options along with the version string.
main · high confidence
Initial configuration and authorization setup
This change introduces the foundational configuration files for the application, including \config.go\ for loading settings from TOML, JSON, or YAML sources (with environment variable overrides), \config.toml\ defining default runtime parameters (such as HTTP port 8080, database connections, and JWT settings), \menu.yaml\ specifying the default admin dashboard menu structure and API permissions, and \model.conf\ establishing the Casbin RBAC authorization model. These files collectively enable the system to start with sensible defaults for logging, security, and UI navigation.
configs · high confidence
Initial domain model for menu action resources
This change introduces the core domain structures for managing menu action resources, including the \MenuActionResource\ struct and its associated repository interface. It defines the data model (ID, ActionID, Method, Path) and provides utility methods to map resources by action ID or method/path combination, along with a repository contract for querying, creating, updating, and deleting these resources.
app/domain/menu/menuactionresource · high confidence
Initial menu domain implementation
Introduced the core domain layer for the application's menu system, defining the Menu entity with fields for hierarchy (ParentID, ParentPath), visibility, and status. Added a Repository interface for data persistence and a Service implementation that handles menu creation, updates, and deletion, including logic for managing parent-child relationships, validating unique names, and associating menu actions and resources.
app/domain/menu, app/infrastructure/menu · high confidence
Initial project scaffolding and configuration
The repository has been initialized with the core configuration files and documentation required to build and run the application. This includes a Dockerfile and dev.Dockerfile for containerization, a Makefile for build and development tasks, and a golangci-lint configuration for code quality. The project also introduces Skaffold for local Kubernetes development, a Renovate configuration for automated dependency updates, and standard repository files such as .editorconfig, .gitignore, and the Apache 2.0 LICENSE. Documentation is provided in English, Simplified Chinese, and Japanese, outlining the DDD architecture and technology stack.
(repo-wide) · high confidence
Initial user repository implementation with GORM persistence
The application now includes a concrete database repository for user management, introducing a GORM-based data access layer. This change adds a \users\ table model and a repository interface implementation that supports creating, reading, updating, and deleting user records, as well as querying users by username, status, role IDs, and general search terms with pagination. The implementation handles the mapping between domain user objects and database models, enabling the user service to persist and retrieve user data from the database.
app/infrastructure/user · high confidence
Introduce GORM database initialization and common query utilities
The application now includes a new GORM infrastructure layer that provides database connection management and common data access helpers. Users can initialize connections to MySQL, PostgreSQL, or SQLite via a configuration struct, with support for table prefixes, connection pooling, and debug logging. The new common utilities simplify transaction handling (including optional row-level locking for MySQL/Postgres), pagination, single-record retrieval, and order parsing, reducing boilerplate in domain services.
app/infrastructure/gormx · high confidence
Introduce pluggable token blacklist storage for authentication
The authentication infrastructure now supports a configurable token blacklist store, allowing the system to invalidate JWTs immediately upon logout or token revocation. This change introduces a \Store\ interface with two concrete implementations: an in-memory/file-based store using \buntdb\ (suitable for development or single-instance deployments) and a Redis-based store (supporting standalone and cluster modes) for production environments. The auth repository uses this store to track revoked tokens, ensuring that a destroyed token cannot be reused even if it has not yet expired, thereby enhancing session security.
app/infrastructure/auth · high confidence
Introduces RBAC repository interface for listing policies
A new repository interface has been added to the RBAC domain to define how role and user policies are retrieved. This interface exposes methods for listing all role policies and user policies, providing a standardized contract for accessing policy data within the application.
app/domain/rbac · high confidence
Introduces dependency injection and application wiring for the API server
The injector package now provides the core wiring logic for the application, using Google Wire to assemble dependencies for the HTTP server, database, and business logic. This includes initializing the Gin engine, GORM database connections (supporting MySQL, PostgreSQL, and SQLite3 with auto-migration), Casbin RBAC enforcement, and logging. The injector also handles server lifecycle management, including graceful shutdown on signals and executing menu data seeds.
injector · high confidence
Introduces user, role, and role-menu domain models with repository interfaces
This change adds the foundational domain layer for user management within the \app/domain/user\ package. It defines the \User\, \Role\, and \RoleMenu\ entities along with their respective repository interfaces (\Repository\), enabling CRUD operations and querying with pagination support. The \user\ package also includes a \Service\ implementation that handles retrieving active users and resolving their associated roles, while the \role\ and \rolemenu\ sub-packages provide the data structures and helper methods (such as \ToMap\ and \ToRoleIDs\) necessary for managing role-based access control relationships. Tests are included to verify the helper logic for these domain objects.
app/domain/user · high confidence
Introduction of Menu Action domain model and repository interface
This change introduces the core domain model for menu actions, defining the \MenuAction\ struct with fields for ID, MenuID, Code, Name, and associated resources. It includes utility methods on the \MenuActions\ collection to facilitate mapping by menu ID or code, and filling resource data. Additionally, a \Repository\ interface is defined to standardize data access operations such as querying, creating, updating, and deleting menu actions, along with a specific method to delete actions by menu ID. Tests are included to verify the mapping and resource-filling logic.
app/domain/menu/menuaction · high confidence
Introduction of contextx package for structured context value management
A new \contextx\ package has been added to the application domain, providing a set of helper functions to store and retrieve specific values within Go contexts. This includes dedicated support for transaction objects (\NewTrans\/\FromTrans\), transaction lock states (\NewTransLock\/\FromTransLock\), user identification (\NewUserID\/\FromUserID\), and distributed tracing identifiers (\NewTraceID\/\FromTraceID\). This change introduces new capabilities for context propagation rather than modifying existing behavior.
app/domain/contextx · high confidence
Introduction of core authentication domain models and repository interfaces
This change introduces the foundational structures for the authentication system within the application. It defines the \Auth\ struct to hold token details (access token, type, expiration) and the \RootUser\ struct for user credentials. Additionally, it establishes the \Repository\ interface for the auth domain, specifying methods for finding root users, generating and destroying tokens, parsing user IDs from access tokens, and managing repository lifecycle. A separate \trans\ repository interface is also added to support transactional execution contexts.
app/domain/auth · high confidence
New API application initialization and dependency injection structure
The injector/api package now provides a structured entry point for initializing the application's core components. This includes setting up the HTTP server with configurable timeouts and TLS support, initializing JWT-based authentication with support for both Redis and BuntDB storage backends, configuring Casbin for role-based access control (RBAC) with auto-loading policies, and building the Gin web engine with middleware for tracing, logging, CORS, GZIP compression, and Swagger documentation. Additionally, it introduces initialization logic for CAPTCHA storage (supporting Redis) and process monitoring via gops.
injector/api · high confidence
New API handlers and request schemas for authentication, user, role, and menu management
This change introduces the HTTP handler layer and request validation schemas for the application's core administrative features. The new \login.go\ handler implements user authentication flows, including login, logout, token refresh, user info retrieval, menu tree queries, and password updates, with integrated captcha verification. The \user.go\, \role.go\, and \menu.go\ handlers provide CRUD operations (create, read, update, delete) and status management (enable/disable) for users, roles, and menus, supporting pagination and query filtering. Corresponding request structs in \request/\ define the input schemas and validation rules for these endpoints, mapping HTTP parameters to domain objects.
app/interfaces/api/handler · high confidence
New API helper utilities for Gin-based request handling and response formatting
A new \gin.go\ file has been added to the API interface layer, introducing a suite of helper functions to standardize how the application handles HTTP requests and responses. These utilities simplify extracting authentication tokens and user IDs from context, parsing JSON, query parameters, and form data with consistent 400 Bad Request error wrapping, and sending structured JSON responses (success, list, paginated, or error) with appropriate HTTP status codes and logging.
app/interfaces/api · high confidence
New API middleware layer for authentication, authorization, and request handling
The application now includes a dedicated middleware package at app/interfaces/api/middleware that provides core request processing capabilities. This adds user authentication via JWT (with a debug fallback to root user), role-based access control using Casbin, and distributed rate limiting via Redis. It also introduces request body copying with gzip support, CORS configuration, structured HTTP logging, panic recovery with stack traces, distributed tracing via X-Request-Id, and static file serving for web assets.
app/interfaces/api/middleware · high confidence
New API response models for health, authentication, and core domain entities
This change introduces a new \app/interfaces/api/response\ package that defines the JSON response structures for the application's API endpoints. It adds specific models for health checks (\HealthCheck\), login flows (\UserLoginInfo\, \LoginCaptcha\, \LoginTokenInfo\), and core domain entities including Users, Roles, Menus, and their associated relationships (e.g., \UserShow\, \RoleMenu\, \MenuTree\). These structs include JSON tags for serialization and helper methods to convert between domain objects and API representations, establishing the contract for how data is returned to clients.
app/interfaces/api/response · high confidence
New application-layer services for authentication, RBAC, and menu management
This change introduces the application layer for the DDD-based admin platform, adding new Go files in app/application that implement core business logic. The Login service handles user verification, token generation/revocation, password updates (with root-user restrictions), and menu tree retrieval. The RbacAdapter integrates Casbin v3 to load and sync role/user policies asynchronously, ensuring access control decisions reflect database changes. The Role and User services manage CRUD operations for roles and users, including role-menu and user-role assignments, while triggering policy updates via the RBAC adapter. Additionally, a Menu service provides basic menu CRUD, and a Seed service populates initial menu data from a YAML configuration file on startup.
app/application · high confidence
New pagination and ordering domain types introduced
A new pagination domain package has been added to the application, providing core data structures for handling paginated data and sorting. Users can now utilize the \Pagination\ struct to represent response metadata (total count, current page, page size) and the \Param\ struct to define request parameters, which includes a default page size of 100 when not specified. Additionally, the package introduces \OrderField\ and \OrderFields\ types to manage sorting logic, supporting ascending or descending directions and offering a helper to append an ID-based descending sort field.
app/domain/pagination · high confidence
New utility packages for hashing, JSON, YAML, structure copying, tracing, and UUID generation
The \pkg/util\ directory now includes several new helper packages to standardize common operations. The \hash\ package provides MD5 and SHA1 hashing functions for byte slices and strings. The \json\ and \yaml\ packages wrap \jsoniter\ and \gopkg.in/yaml.v3\ respectively, exposing standard marshaling, unmarshaling, and encoding/decoding functions, with \json\ additionally offering a \MarshalToString\ utility. The \structure\ package uses \copier\ to facilitate deep copying between Go structs. The \trace\ package introduces a \NewTraceID\ function that generates unique identifiers based on process ID, timestamp, and an atomic counter. Finally, the \uuid\ package wraps \github.com/google/uuid\ to provide convenient functions for generating and converting UUIDs.
pkg/util · high confidence
RBAC repository implementation for policy generation
Added the RBAC repository implementation in \app/infrastructure/rbac/repository.go\ to generate access control policies. This new component aggregates data from role, user, and menu repositories to produce Casbin-style policies: \ListRolesPolicies\ constructs permission rules (p) by mapping roles to their associated menu actions and paths, while \ListUsersPolicies\ constructs user-role assignment rules (g) by linking active users to their assigned roles.
app/infrastructure/rbac · high confidence
Behavioural changes
Introduction of structured HTTP error handling with typed response codes
The application now uses a dedicated error domain in \app/domain/errors\ to standardize how errors are represented and returned to clients. This change introduces a \ResponseError\ type that explicitly maps internal errors to HTTP status codes (such as 400, 401, 404, 405, 429, and 500) and specific error codes. Pre-defined constants like \ErrBadRequest\, \ErrNotFound\, and \ErrInternalServer\ provide consistent, typed error responses for common scenarios, replacing ad-hoc error handling with a structured approach that ensures clients receive predictable HTTP status codes and messages.
app/domain/errors · high confidence
Test coverage
Added end-to-end test suite for API integration
A new end-to-end test file has been added to the \test/e2e\ directory, establishing a full integration test harness for the application. This suite initializes a test server with a SQLite database, configures essential services such as JWT authentication and captcha storage, and seeds initial data (including a root user) to validate API behavior in a realistic environment.
test · high confidence
Dependencies
Updated Go dependencies and upgraded to Go 1.26
The project's dependency manifest (go.mod) has been updated to require Go 1.26.0 and includes significant version bumps for core libraries, including the Gin web framework (v1.12.0), the CLI library urfave/cli/v3 (v3.13.0), and the Redis client go-redis/v9 (v9.22.0). Additional updates were applied to logging (logrus v1.10.2), authentication (jwt/v5 v5.3.1), authorization (casbin/v3 v3.11.0), and database drivers (gorm v1.31.2, postgres driver v1.6.3).
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 69 → 66 (-3.7)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 97 → 96 (-1.0)
- Architecture 99 → 76 (-23.9)
- Maturity 69 → 70 (+1.5)
- Readiness 66 → 54 (-12.6)
- Security 62 → 76 (+14.0)
- Domain Modelling 100 → 100 (+0.0)
Resolved (27)
- Change coupling: user.go ↔ api.go (app/application/user.go)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (app/infrastructure/menu/repository.go)
- Duplicated block (11 lines × 2) (app/infrastructure/menu/repository.go)
- Duplicated block (11 lines × 2) (app/interfaces/api/handler/role.go)
- Duplicated block (12 lines × 2) (app/domain/user/rolemenu/rolemenu.go)
- Duplicated block (12 lines × 4) (app/infrastructure/menu/menuaction/repository.go)
- Duplicated block (13 lines × 2) (app/interfaces/api/handler/menu.go)
- Duplicated block (15 lines × 2) (app/application/role.go)
- Duplicated block (15 lines × 2) (app/domain/menu/menu.go)
- Duplicated block (16 lines × 2) (pkg/captcha/siprng.go)
- Duplicated block (9 lines × 2) (app/infrastructure/menu/repository.go)
- Duplicated block (9 lines × 7) (app/infrastructure/menu/menuaction/repository.go)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 7 more
New (55)
- Dependency pinned to a stale untagged commit: github.com/koding/multiconfig
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 7) (pkg/captcha/siprng.go)
- Duplicated block (11 lines × 2) (app/infrastructure/menu/repository.go)
- Duplicated block (12 lines × 2) (pkg/captcha/siprng.go)
- Duplicated block (12 lines × 4) (app/infrastructure/menu/menuaction/repository.go)
- Duplicated block (13 lines × 2) (app/domain/user/rolemenu/rolemenu.go)
- Duplicated block (13 lines × 5) (pkg/captcha/siprng.go)
- Duplicated block (16 lines × 2) (app/application/role.go)
- Duplicated block (16 lines × 2) (app/interfaces/api/handler/role.go)
- Duplicated block (19 lines × 2) (app/domain/menu/menu.go)
- Duplicated block (19–20 lines × 2) (app/interfaces/api/handler/menu.go)
- Duplicated block (6 lines × 2) (app/application/rbac.go)
- Duplicated block (6 lines × 2) (app/infrastructure/menu/repository.go)
- Duplicated block (7 lines × 2) (app/application/role.go)
- Duplicated block (7 lines × 2) (app/domain/menu/menuaction/menuaction.go)
- Duplicated block (7 lines × 2) (app/domain/menu/menuaction/menuaction.go)
- Duplicated block (7 lines × 2) (app/domain/user/role/role.go)
- Duplicated block (7 lines × 2) (app/domain/user/rolemenu/rolemenu.go)
- …and 35 more
Changes since last survey
- 17 commits — 3 feature/other, 14 fixes
By area
- (root) — 15 commits
- (repo) — 1 commit
- .github/workflows — 1 commit
Notable commits
- fix: fix(deps): update module github.com/casbin/casbin/v3 to v3.11.0 (#75)
- fix: fix(deps): update module github.com/gin-contrib/cors to v1.7.8 (#83)
- fix: fix(deps): update module github.com/gin-contrib/gzip to v1.2.7 (#84)
- fix: fix(deps): update module github.com/redis/go-redis/v9 to v9.22.0 (#76)
- fix: fix(deps): update module github.com/sirupsen/logrus to v1.10.0 (#77)
- fix: fix(deps): update module github.com/sirupsen/logrus to v1.10.1 (#80)
- fix: fix(deps): update module github.com/sirupsen/logrus to v1.10.2 (#82)
- fix: fix(deps): update module github.com/stretchr/testify to v1.12.0 (#79)
- fix: fix(deps): update module github.com/stretchr/testify to v1.12.1 (#81)
- fix: fix(deps): update module github.com/urfave/cli/v3 to v3.11.0 (#78)
- fix: fix(deps): update module github.com/urfave/cli/v3 to v3.12.0 (#88)
- fix: fix(deps): update module github.com/urfave/cli/v3 to v3.13.0 (#89)
- fix: fix(deps): update module gorm.io/driver/postgres to v1.6.2 (#74)
- fix: fix(deps): update module gorm.io/driver/postgres to v1.6.3 (#87)
- change: Merge pull request #73 from linzhengen/renovate/actions-setup-go-7.x
- change: chore(deps): update actions/setup-go action to v7
- change: chore: bump up go pkgs
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
linzhengen/ddd-gin-admin was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit d54752e06b80ee989029528dfa3b8ab0a49ad267 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.